Stuffy Squirrel is a financially motivated dropcatch actor active since at least 2020. It acquires expired domains, including domains formerly used in malicious infrastructure and still referenced by compromised websites, allowing it to inherit residual victim traffic without newly compromising the affected sites. The actor controls more than 500 domains and operates a traffic distribution system across multiple generations of infrastructure. Stuffy Squirrel conceals malicious JavaScript within legitimate-looking web libraries, applies server-side validation and selective traffic delivery, and requires real user interaction before triggering popunder behavior, hindering automated analysis. It monetizes redirected traffic through affiliate advertising and popunder networks, including unwanted push-notification and advertising campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another group observed acquiring and abusing expired domains; the article generally associates such groups with redirecting existing traffic to malware, advertising fraud, or scams.
Tracked as another group monetizing expired domains by capturing residual traffic from previous owners and redirecting it to ad networks, scam sites, and other cybercriminals.
Cybercriminal dropcatch actor operating since at least 2020 that reacquires expired malicious domains to inherit victim traffic, uses a TDS, injects malicious code into legitimate scripts, and monetizes redirected traffic through affiliate advertising networks.
A scavenger actor that acquires expired domains previously compromised by other attackers and inherits existing infection traffic.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.